Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-78030: libdbi-perl lets attackers gain higher privileges
CVE-2026-78030 · published today
Summary
The libdbi-perl component used in Debian 12 can be tricked into running code with higher system rights. This could let an attacker take control of the server or access sensitive data. Apply the updated libdbi-perl packages from your distribution as soon as possible.
What to do
- Update debian libdbi-perl to version 1.653-1.
- Update libdbi-perl to version 1.643-4+deb12u1.aikido.2.
- Update rootio-libdbi-perl to version 1.643-4+deb12u1.aikido.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:14.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:22.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:24.04:LTS | canonical | libdbi-perl | All versions |
| Ubuntu:26.04:LTS | canonical | libdbi-perl | All versions |
| Debian:12 | debian | libdbi-perl | All versions |
| Debian:14 | debian | libdbi-perl |
< 1.653-1 Fix: upgrade to 1.653-1
|
| Root:Debian:12 | – | libdbi-perl |
< 1.643-4+deb12u1.aikido.2 Fix: upgrade to 1.643-4+deb12u1.aikido.2
|
| Root:Debian:12 | – | rootio-libdbi-perl |
< 1.643-4+deb12u1.aikido.2 Fix: upgrade to 1.643-4+deb12u1.aikido.2
|
Original advisory text
CVE-2026-78030 in libdbi-perl - Patched by Root
Root has patched CVE-2026-78030 in the libdbi-perl package for Root:Debian:12. Multiple fixed versions available.
References
- https://github.com/perl5-dbi/dbi/commit/315c6ce703b8b3cbe9188062d9ec80730293554a... Patch
- https://metacpan.org/release/HMBRAND/DBI-1.653/changes Vendor Advisory
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-wqmw-wqwx-3fr7 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/09/19/4 URL
- https://cpan.org/modules URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78030... Vendor Advisory
- https://github.com/perl5-dbi/dbi Product
- https://nvd.nist.gov/vuln/detail/CVE-2026-78030 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-78030 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-78030 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-78030 Vendor Advisory
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Timeline
Published28 Sep 2026
Updated28 Sep 2026
First seen14 Sep 2026
Sources
UBUNTU-CVE-2026-78030 · OSV
CVE-2026-78030 · NVD
CVE-2026-78030 · MITRE
DEBIAN-CVE-2026-78030 · OSV
CVE-2026-78030 · OSV
GHSA-wqmw-wqwx-3fr7 · GHSA
Track software like this
Free during beta